Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

3237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.33%—OscommerceAI3/8/202612/8/2026
A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is…
AplazadaAlta (7.5)0.41%—Multidots Product Attachment FOR WoocommerceAI2/8/202626/8/2026
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
AplazadaAlta (7.5)0.41%—AI Chatbot FOR WoocommerceAI2/8/202626/8/2026
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to…
AplazadaCrítica (9.8)0.70%—Wpwebelite Woocommerce Social LoginAI2/8/202612/8/2026
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or…
AplazadaMedia (5.3)0.40%—Woocommerce Paypal PaymentsAI1/8/202629/9/2026
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This…
AplazadaMedia (6.5)0.30%—Automattic Woocommerce PaymentsAI1/8/202626/8/2026
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
AplazadaMedia (5.3)0.30%—Direct Payments FOR WoocommerceAI1/8/202626/8/2026
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,…
AplazadaAlta (8.8)0.81%—Subscriptions FOR WoocommerceAI1/8/202612/8/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only…
AplazadaAlta (8.1)0.39%—Product Feed Manager FOR WoocommerceAI31/7/202626/8/2026
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
AplazadaMedia (6.1)0.18%—Ecommerce Fruits BazarAI30/7/20261/10/2026
Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
AplazadaCrítica (9.8)0.39%—Ecommerce-project-with-php-and-mysqli-fruits-bazarAI30/7/20261/10/2026
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
AplazadaAlta (8.3)0.18%—Softtr Information Technology Trade LTD E-commerce PackAI30/7/202631/7/2026
Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49.
AplazadaAlta (8.2)0.44%—FTC Software IT Services FTC E-commerce Management PanelAI30/7/202630/7/2026
Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.
AplazadaAlta (7.2)0.58%—Subscriptions FOR WoocommerceAI30/7/202630/7/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible…
AplazadaMedia (5.9)0.29%—Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI30/7/202630/7/2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily…
AplazadaMedia (5.3)0.30%—Payu CommerceproAI29/7/202610/8/2026
The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
AplazadaMedia (4.3)0.40%—Eventbooking Event Booking Manager FOR WoocommerceAI29/7/202630/7/2026
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (8.8)0.52%—Wpexperts Wholesale FOR WoocommerceAI29/7/202630/7/2026
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with…
AplazadaMedia (4.4)0.52%—SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack…
AplazadaMedia (6.5)0.37%—Yookassa Yukassa FOR WoocommerceAI27/7/202627/7/2026
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
AplazadaAlta (7.5)0.35%—Stripe FOR WoocommerceAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
AplazadaCrítica (9)0.67%—Facturone Para Woocommerce CON VerifactuAI27/7/202627/7/2026
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible…
AplazadaAlta (8.1)0.41%💥 PoCCustom Fields Account Registration FOR WoocommerceAI27/7/202627/7/2026
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator…
AplazadaMedia (6.5)0.79%—Themehigh Checkout Field Editor FOR WoocommerceAI25/7/202627/7/2026
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary…
AplazadaMedia (6.4)0.33%—Berocket Brands FOR WoocommerceAI24/7/202624/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…